# service-principal

Source: https://startwithidentity.com/glossary/service-principal/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

A service principal is the identity an application or automated workload uses to sign in to Microsoft Entra ID and access Azure or Microsoft Graph resources: the instance of an app registration inside a specific tenant.

Service principals authenticate with a client secret, a certificate, or a federated credential, and receive permissions through Azure role assignments and Microsoft Graph application permissions. Managed identities are a special kind of service principal whose credentials Azure creates and rotates, so there is no secret to leak. The recurring problems are the ones common to every [non-human identity](https://startwithidentity.com/glossary/nhi/): client secrets copied into code, tickets and chat, broad roles such as Contributor granted at subscription scope for convenience, and no named owner to review them. In September 2026, Microsoft described an attacker using [a service principal whose secret appeared in a public GitHub issue](https://startwithidentity.com/blog/2026-09-28-jadepuffer-used-leaked-service-principal-credentials-to-wipe-azure-tenants/) to delete recovery locks and destroy Azure resources in seven minutes.

See also: [workload identity](https://startwithidentity.com/glossary/workload-identity/), [workload identity federation](https://startwithidentity.com/glossary/workload-identity-federation/), [client credentials](https://startwithidentity.com/glossary/client-credentials/), [Microsoft Entra](https://startwithidentity.com/vendors/iam/microsoft-entra/)
